Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 2.2.0
affected
Default status
unaffected
0.0.0 (semver) before 2.2.0
affected
Default status
unaffected
0.0.0 (semver) before 2.2.0
affected
Description
A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
0.0.0 (semver) before 2.2.0
0.0.0 (semver) before 2.2.0
0.0.0 (semver) before 2.2.0
Credits
Noam Moshe from Claroty Team82
Tomer Goldschmidt from Claroty Team82
References
certvde.com/de/advisories/VDE-2025-097